Vulnerability index

Browse CVEs

73 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Itop MEDIUM 6.1
CVE-2025-64167

Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to a cross-site scripting attack (leading t…

Fix: 2.7.13 / 3.2.2+
Fix from $1,600 2025-11-10
Itop MEDIUM 6.5
CVE-2025-49145

Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, a user that has enough rights to create webhooks (most…

Fix: 2.7.13 / 3.2.2+
Fix from $1,600 2025-11-10
Itop MEDIUM 6.1
CVE-2025-48065

Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site scripting when a field with a…

Fix: 2.7.13 / 3.2.2+
Fix from $1,600 2025-11-10
Itop MEDIUM 5.4
CVE-2025-48055

Combodo iTop is a web based IT service management tool. In versions prior to 3.2.2, when displaying content in a browse brick in the user portal, a c…

Fix: 3.2.2+
Fix from $1,600 2025-11-10
Itop MEDIUM 6.1
CVE-2025-47932

Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site scripting when a dashboard i…

Fix: 2.7.13 / 3.2.2+
Fix from $1,600 2025-11-10
Itop HIGH 7.2
CVE-2025-47286

Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, an administrator can, by editing the configuration of …

Fix: 2.7.13 / 3.2.2+
Fix from $1,950 2025-11-10
Itop MEDIUM 6.1
CVE-2025-47773

Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site scripting when a dashboard is…

Fix: 2.7.13 / 3.2.2+
Fix from $1,600 2025-11-10
Itop MEDIUM 5.0
CVE-2025-24969

iTop is an web based IT Service Management tool. Prior to version 3.2.1, a portal user can see any other contacts picture by changing the picture ID …

Fix: 3.2.1+
Fix from $1,600 2025-05-14
Itop HIGH 8.5
CVE-2025-24022

iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, server code execution is possible through the frontend o…

Fix: 2.7.12 / 3.1.3+
Fix from $1,950 2025-05-14
Itop MEDIUM 5.3
CVE-2025-24026

iTop is an web based IT Service Management tool. Versions prior to 3.2.1 are vulnerable to regular expression denial of service (ReDoS) that may, und…

Fix: 3.2.1+
Fix from $1,600 2025-05-14
Itop MEDIUM 5.0
CVE-2025-24021

iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account having portal access can set valu…

Fix: 2.7.12 / 3.1.3+
Fix from $1,600 2025-05-14
Itop MEDIUM 6.5
CVE-2024-52601

iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account having portal access can have rea…

Fix: 2.7.12 / 3.1.3+
Fix from $1,600 2025-05-14
Itop MEDIUM 6.3
CVE-2024-56157

iTop is an web based IT Service Management tool. Prior to versions 3.1.3 and 3.2.1, by filling malicious code in a CSV content, a cross-site scriptin…

Fix: 3.1.3 / 3.2.1+
Fix from $1,600 2025-05-14
Itop MEDIUM 5.4
CVE-2025-27139

Combodo iTop is a web based IT service management tool. Versions prior to 2.7.12, 3.1.2, and 3.2.0 are vulnerable to cross-site scripting when the pr…

Fix: 2.7.12 / 3.1.2+
Fix from $1,600 2025-02-25
Itop CRITICAL 9.6
CVE-2024-54139

Combodo iTop is an open source and web-based IT service management platform. Prior to versions 2.7.11, 3.1.2, and 3.2.0., iTop has a cross-site scrip…

Fix: 2.7.11 / 3.1.2+
Fix from $2,300 2024-12-13
Itop HIGH 8.8
CVE-2024-52002

Combodo iTop is a simple, web based IT Service Management tool. Several url endpoints are subject to a Cross-Site Request Forgery (CSRF) vulnerabilit…

Fix: 3.2.0+
Fix from $1,950 2024-11-08
Itop MEDIUM 6.1
CVE-2024-52000

Combodo iTop is a simple, web based IT Service Management tool. Affected versions are subject to a reflected Cross-site Scripting (XSS) exploit by wa…

Fix: 3.2.0+
Fix from $1,600 2024-11-08
Itop HIGH 7.1
CVE-2024-51995

Combodo iTop is a web based IT Service Management tool. An attacker can request any `route` we want as long as we specify an `operation` that is allo…

Fix: 3.2.0+
Fix from $1,950 2024-11-07
Itop MEDIUM 5.4
CVE-2024-51994

Combodo iTop is a web based IT Service Management tool. In affected versions uploading a text file containing some java script in the portal will tri…

Fix: 2.7.11 / 3.1.2+
Fix from $1,600 2024-11-07
Itop HIGH 8.8
CVE-2024-51740

Combodo iTop is a simple, web based IT Service Management tool. This vulnerability can be used to create HTTP requests on behalf of the server, from …

Fix: 2.7.11 / 3.0.5+
Fix from $1,950 2024-11-05
Itop MEDIUM 5.3
CVE-2024-51739

Combodo iTop is a simple, web based IT Service Management tool. Unauthenticated user can perform users enumeration, which can make it easier to brute…

Fix: 2.7.11 / 3.0.5+
Fix from $1,600 2024-11-05
Itop HIGH 8.8
CVE-2024-31998

Combodo iTop is a simple, web based IT Service Management tool. A CSRF can be performed on CSV import simulation. This issue has been fixed in versio…

Fix: 3.1.2+
Fix from $1,950 2024-11-05
Itop MEDIUM 5.8
CVE-2024-32870

Combodo iTop is a simple, web based IT Service Management tool. Server, OS, DBMS, PHP, and iTop info (name, version and parameters) can be read by an…

Fix: 2.7.11 / 3.0.5+
Fix from $1,600 2024-11-05
Itop MEDIUM 6.1
CVE-2023-34443

Combodo iTop is a simple, web based IT Service Management tool. When displaying page Run queries Cross-site Scripting (XSS) are possible for scripts …

Fix: 2.7.9 / 3.0.4+
Fix from $1,600 2024-11-05
Itop MEDIUM 6.1
CVE-2023-34444

Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.searchform.php XSS are possible for scripts outside of scr…

Fix: 2.7.9 / 3.0.4+
Fix from $1,600 2024-11-05
Itop MEDIUM 6.1
CVE-2023-34445

Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.render.php XSS are possible for scripts outside of script …

Fix: 2.7.9 / 3.0.4+
Fix from $1,600 2024-11-05
Itop MEDIUM 6.1
CVE-2024-31448

Combodo iTop is a simple, web based IT Service Management tool. By filling malicious code in a CSV content, an Cross-site Scripting (XSS) attack can …

Fix: 3.1.2+
Fix from $1,600 2024-11-05
Itop CRITICAL 9.8
CVE-2023-48710

iTop is an IT service management platform. Files from the `env-production` folder can be retrieved even though they should have restricted access. …

Fix: 2.7.10 / 3.0.4+
Fix from $2,300 2024-04-15
Itop HIGH 8.0
CVE-2023-48709

iTop is an IT service management platform. When exporting data from backoffice or portal in CSV or Excel files, users' inputs may include malicious …

Fix: 2.7.9 / 3.0.4+
Fix from $1,950 2024-04-15
Itop MEDIUM 6.1
CVE-2023-47622

iTop is an IT service management platform. When dashlet are refreshed, XSS attacks are possible. This vulnerability is fixed in 3.0.4 and 3.1.1.

Fix: 3.0.4 / 3.1.1+
Fix from $1,600 2024-04-15